feishu-calendar
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill exclusively interacts with official Feishu API endpoints at open.feishu.cn. No unauthorized or suspicious domains are contacted.- [SAFE]: Secret management follows best practices by using placeholders like YOUR_TOKEN in example commands instead of hardcoding sensitive credentials.- [SAFE]: No obfuscation, persistence mechanisms, or unauthorized command execution patterns were found in the provided documentation or examples.- [PROMPT_INJECTION]: The skill processes external data (calendar event summaries and descriptions) which presents a theoretical indirect prompt injection surface; however, the skill does not possess high-privilege capabilities like shell execution or file system modification that would make this surface exploitable.
Audit Metadata